wevtutil.exe Event Log Clearing - Security/System/Application (T1070.001)
Detects the execution of 'wevtutil.exe' with the 'cl' or 'clear-log' arguments targeted at primary Windows Event Logs (Security, System, or Application). This activity is commonly associated with an adversary attempting to clear audit logs to conceal malicious actions during an intrusion.
SentinelOne

